Operational resilience you can evidence, not just describe

DORA, third party risk, incident reporting and the evidence a supervisor or a bank client will ask for. Wizard keeps it structured and current.

Request a demo or assess your compliance maturity. No email needed to start the assessment.

The requirement is continuous, the process is periodic

DORA asks for something most compliance work is not built for: continuous evidence. A register of information on ICT third parties, incident classification and reporting within tight windows, resilience testing, and exit strategies for critical providers.

Most of that exists in some form. The third party register is a spreadsheet updated when someone remembers. The incident process is a document nobody has run through since it was written. The exit strategy was drafted during onboarding.

None of that is negligence. It is what happens when requirements are continuous and processes are annual.

Built for the report, not the state

Point in time by design.

Annual assessments and periodic reviews describe a moment. DORA asks about now.

Third party risk sits apart.

Vendor management, contracts and resilience testing usually live in different places with different owners, which makes producing a register of information a data gathering exercise every time.

Incident reporting depends on process discipline alone.

Tight reporting windows require classification and escalation to work under pressure, at speed, out of hours.

Structure that holds under supervision

A third party register that stays current.

Criticality, contract dates, review cycles and named owners, maintained as part of the work rather than rebuilt for each submission.

Incident classification defined in advance.

Escalation paths and severity criteria agreed before they are needed, so a tight reporting window is a process rather than a scramble.

Evidence that accumulates through the work.

Producing a supervisory response means filtering what is already recorded.

The same system as your other obligations.

ISO 27001, GDPR and DORA share more than they differ. Running them separately duplicates the work three times.

Where Wizard fits, and where it does not

Against enterprise GRC platforms.

For a large regulated institution with a dedicated risk function and years of implementation budget, those platforms exist for good reasons. Wizard is not built for that organisation.

Against your existing risk framework.

If you have a working framework maintained by people who own it, the question is whether the evidence behind it can be produced on request. If it can, you may not need this.

Against a specialist DORA tool.

Some exist and are built specifically for the regulation. If DORA is your only obligation and you have no interest in a broader system, one of those may suit you better.

What Wizard is not.

It is not regulatory advice, it does not interpret DORA for your business model, and it does not replace a risk function.

Built by people who have been audited, and who have audited others

Wizard was designed by people who spent years building these systems inside regulated organisations before they built software for them. What follows is their professional background. These were consultancy and audit engagements, not Wizard implementations, and we mention them because the design decisions in this product came directly from that work.

Eoghan Kenny, Co-Founder and CEO

Over twenty years implementing governance, risk and compliance systems in regulated organisations, including work as an external Data Protection Officer. The parts of Wizard that deal with ownership and review cycles exist because he watched those two things fail more often than anything else.

Derek Mizak, Co-Founder and CTO

Over thirty years across cybersecurity, audit and systems architecture, including auditing management systems from the outside, which means he has seen which evidence holds under examination and which only looks like it does. Wizard's evidence model is built around what has to be produced under examination, not around what is convenient to record.

Dominic O'Toole, Co-Founder and CPO

Over twenty years building enterprise software. His job on this product is making a system this structured usable by people who are responsible for compliance without being full-time specialists.

None of this makes Wizard the right fit for every organisation. It does mean the people who designed it have implemented, maintained and audited the systems it manages.

Common questions

Does Wizard support DORA specifically?

[PLACEHOLDER: to confirm with Derek. Answer plainly, including whether the register of information is prebuilt or configured, and whether incident classification maps to DORA criteria.]

Can it produce a register of information?

[PLACEHOLDER: to confirm with Derek.]

We are not directly regulated, but our bank clients ask us these questions. Does this apply?

Frequently yes. Obligations flow down through contracts, and suppliers to regulated entities are often asked to evidence the same things without being subject to the regulation themselves.

How does this relate to ISO 27001 work we already do?

There is meaningful overlap in controls, supplier management and incident handling. Running them in the same system means the overlap is structural rather than duplicated.

Where is our data held?

Microsoft Azure, with enterprise-grade access controls. Our sub-processor list and data processing agreement are published on the site.

Are you certified to ISO 27001 yourselves?

Wizard is built to ISO 27001 requirements and hosted on Microsoft Azure in Ireland, with our security architecture, Data Processing Agreement and sub-processor list published on our Legal, Privacy and Security page.

What does it cost?

Standard plans start at 600 euro per month billed annually for up to 30 active users. Consultant accounts are free and do not count toward the limit.

See what your evidence looks like on request

Request a demo and we will walk through how this works for your obligations and your suppliers. If you would rather see where you stand first, the Health Check takes five minutes. Request a demo or start the Health Check.

Hosted on Microsoft Azure. DPA and sub-processor list published. Demo requests answered within one business day by a person. Free consultant accounts. Based in Ireland.